xoxys.nginx/tasks/install.yml

129 lines
3.1 KiB
YAML
Raw Normal View History

2017-07-15 13:45:46 +00:00
---
2017-12-23 11:30:23 +00:00
- block:
2017-12-24 16:45:37 +00:00
- name: Add nginx repository
2017-12-23 11:30:23 +00:00
yum_repository:
name: nginx
file: nginx
description: NGINX High Performance Web Server
2017-12-23 12:05:52 +00:00
baseurl: "https://nginx.org/packages/centos/{{ ansible_distribution_major_version }}/$basearch/"
2017-12-23 11:30:23 +00:00
gpgkey: https://nginx.org/keys/nginx_signing.key
gpgcheck: yes
2018-08-09 19:20:06 +00:00
when: nginx_official_repo_enabled
2017-12-23 11:30:23 +00:00
- name: Installing nginx
yum:
name: nginx
state: installed
2017-12-24 13:05:27 +00:00
- name: Create group '{{ nginx_group }}'
group:
name: "{{ nginx_group }}"
state: present
when: nginx_group != "nginx"
- name: Create user '{{ nginx_user }}'
user:
name: "{{ nginx_user }}"
group: "{{ nginx_group }}"
createhome: no
shell: /sbin/nologin
when: nginx_user != "nginx"
2017-12-23 11:30:23 +00:00
- name: Prepare vhost directories
file:
2018-08-09 19:20:06 +00:00
path: "{{ item }}"
2017-12-23 11:30:23 +00:00
state: directory
owner: nginx
group: nginx
mode: 0750
with_items:
2018-08-09 19:20:06 +00:00
- "{{ nginx_vhosts_dir }}"
- "{{ nginx_vhosts_dir }}/default"
2017-12-23 11:30:23 +00:00
- name: Prepare nginx directories
file:
2018-08-09 19:20:06 +00:00
path: "{{ item }}"
2017-12-23 11:30:23 +00:00
state: directory
owner: root
group: root
mode: 0640
with_items:
- /etc/nginx/sites-available
- /etc/nginx/sites-enabled
- name: Update nginx.conf
template:
2018-08-09 19:20:06 +00:00
src: etc/nginx/nginx.conf.j2
dest: "/etc/nginx/nginx.conf"
2017-12-23 11:30:23 +00:00
owner: root
group: root
mode: 0640
2017-12-24 16:36:43 +00:00
validate: /sbin/nginx -t -c %s
2018-08-12 09:31:12 +00:00
notify: __nginx_reload
2017-12-23 11:30:23 +00:00
- name: Remove default.conf from conf.d
file:
path: /etc/nginx/conf.d/default.conf
state: absent
2018-08-11 13:33:16 +00:00
- name: Update header.conf
2017-12-23 11:30:23 +00:00
template:
2018-08-11 12:59:43 +00:00
src: etc/nginx/conf.d/header.conf.j2
dest: /etc/nginx/conf.d/header.conf
2017-12-23 11:30:23 +00:00
owner: root
group: root
mode: 0640
2018-08-13 19:50:09 +00:00
validate: bash -c 'nginx -t -c /dev/stdin <<< "events {worker_connections 1;} http { include %s; }"'
2018-08-12 09:31:12 +00:00
notify: __nginx_reload
2017-12-23 11:30:23 +00:00
- name: Open ports in iptables
iptables_raw:
name: allow_nginx_ports
state: present
rules: '-A INPUT -p tcp -m multiport --dports {{ nginx_open_ports|join(",") }} -j ACCEPT'
when: nginx_iptables_enabled
2018-09-26 22:06:07 +00:00
- name: Set selinux booleans
seboolean:
name: "{{ item.name }}"
state: "{{ item.state }}"
persistent: "{{ item.persistent }}"
with_items: "{{ nginx_set_sebooleans }}"
when: nginx_set_sebooleans
2017-12-23 11:30:23 +00:00
become: True
become_user: root
2017-12-22 20:31:20 +00:00
2018-08-12 09:31:12 +00:00
- block:
- name: Add default page
template:
src: var/www/vhosts/default/index.html.j2
dest: /var/www/vhosts/default/index.html
owner: nginx
group: nginx
mode: 0750
when: nginx_default_page_enabled
become: True
become_user: nginx
2017-12-23 11:25:55 +00:00
- block:
2018-08-11 12:59:43 +00:00
- name: Add default page configuration file
template:
2018-08-12 19:42:13 +00:00
src: etc/nginx/sites-available/default.j2
dest: /etc/nginx/sites-available/default
2017-12-23 11:25:55 +00:00
owner: root
group: root
2018-08-11 12:59:43 +00:00
mode: 0640
2018-08-12 09:31:12 +00:00
notify: __nginx_reload
2017-12-23 11:25:55 +00:00
2018-08-11 12:59:43 +00:00
- name: Enable default page
file:
src: /etc/nginx/sites-available/default
dest: /etc/nginx/sites-enabled/default
2017-12-23 11:25:55 +00:00
owner: root
group: root
2018-08-11 12:59:43 +00:00
state: link
2018-08-12 09:31:12 +00:00
notify: __nginx_reload
2018-08-11 12:59:43 +00:00
when: nginx_default_page_enabled
2017-12-23 11:25:55 +00:00
become: True
become_user: root